
DeMomentSomTres Gift Ticket Security & Risk Analysis
wordpress.org/plugins/demomentsomtres-wc-cadeauPDF Gift Cards for WooCommerce
Is DeMomentSomTres Gift Ticket Safe to Use in 2026?
Generally Safe
Score 100/100DeMomentSomTres Gift Ticket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "demomentsomtres-wc-cadeau" plugin, version v202201120000, reveals a largely positive security posture concerning direct attack vectors and data handling. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and no unprotected entry points. Furthermore, there are no recorded dangerous functions, file operations, or external HTTP requests. All SQL queries utilize prepared statements, and there are no recorded vulnerabilities (CVEs) in its history. However, a significant concern arises from the complete lack of output escaping. With 100% of outputs unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that could be executed by unsuspecting users.
The plugin's vulnerability history is clean, which is a positive indicator. The absence of known CVEs suggests that the developers have either been diligent in maintaining security or the plugin hasn't been a target of widespread vulnerability discovery. The taint analysis also shows no identified flows with unsanitized paths, further reinforcing the lack of direct exploitable data flows detected by this analysis. The presence of the 'dompdf' library, while not inherently a vulnerability, could become a risk if it's an outdated version with known security flaws; this is not explicitly stated in the provided data. In conclusion, while the plugin demonstrates strong practices in preventing direct access and protecting database interactions, the critical oversight in output escaping creates a significant security weakness that requires immediate attention.
Key Concerns
- 0% of outputs properly escaped
- Bundled library: dompdf
DeMomentSomTres Gift Ticket Security Vulnerabilities
DeMomentSomTres Gift Ticket Code Analysis
Bundled Libraries
Output Escaping
DeMomentSomTres Gift Ticket Attack Surface
WordPress Hooks 12
Maintenance & Trust
DeMomentSomTres Gift Ticket Maintenance & Trust
Maintenance Signals
Community Trust
DeMomentSomTres Gift Ticket Alternatives
DeMomentSomTres WooCommerce Default Price
demomentsomtres-woocommerce-default-price
Forces the default product variation price as the default product price.
Extra Shortcodes
extra-shortcodes
[extra_archives], [extra_taxonomies], [bloginfo show="name"], [date format="l jS \of F Y"], [date_i18n], [time]
Category Archives Block
category-archives-block
Displays a monthly or yearly archive of posts for one or more specific categories.
Custom Query Blocks
post-type-archive-mapping
Map your archives to pages. Map 404 and term archives as well.
Posts per Cat
posts-per-cat
Group recent posts by category and show them inside boxes organized to columns.
DeMomentSomTres Gift Ticket Developer Profile
15 plugins · 340 total installs
How We Detect DeMomentSomTres Gift Ticket
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/demomentsomtres-wc-cadeau/css/wccadeau.css/wp-content/plugins/demomentsomtres-wc-cadeau/js/wccadeau.js/wp-content/plugins/demomentsomtres-wc-cadeau/js/wccadeau.jsdemomentsomtres-wc-cadeau/css/wccadeau.css?ver=demomentsomtres-wc-cadeau/js/wccadeau.js?ver=HTML / DOM Fingerprints
dms3-wccadeaudata-dms3-wccadeau-recipient-namedata-dms3-wccadeau-guestsdata-dms3-wccadeau-validitywindow.dms3_wccadeau_ajaxurlwindow.dms3_wccadeau_id_productwindow.dms3_wccadeau_recipient_namewindow.dms3_wccadeau_guestswindow.dms3_wccadeau_validity